Guidelines for remote access VPNs

Review these guidelines before configuring and managing remote access VPN policies.

General guidelines

  • Ensure that only one administrator modifies the policy at a time. The web interface allows multiple concurrent sessions, but only the last saved configuration remains.

  • Ensure that you unassign the remote access VPN policy associated with a Firewall Threat Defense device before moving it to a different domain.

  • Verify the ciphers for the remote access VPN policy before deployment:

    • For SSL: Choose Devices > Platform Settings, edit a policy. From the left pane, click SSL > RA-VPN.

    • For IPsec-IKEv2: Choose Secure Connections > Remote Access VPN, edit a remote access policy. Click the Advanced tab and from the left pane, choose IPsec.

  • Do not run curl commands, including HTTP HEAD requests, on the remote access VPN headend device because these commands are not supported.

  • Ensure third-party clients provide a valid user agent because the Firewall Threat Defense device rejects VPN sessions with a null user agent.

  • Configure browser proxy using FlexConfig.

  • When Bypass Access Control policy for decrypted traffic is disabled and a downloadable access control list (DACL) is applied, decrypted traffic is evaluated against the access control policy (ACP) first. Traffic permitted by the ACP is then evaluated against the DACL; traffic denied by the ACP is not evaluated further.

NAT guidelines

  • Verify the NAT rules on the Firewall Threat Defense device to ensure that they do not disrupt the remote access VPN traffic.

  • Enable route lookup for any NAT rule applied to a remote access VPN network that uses DHCP. This configuration ensures that the device identifies the correct egress interface for DHCP request forwarding.

Certificate guidelines

  • Install the identity certificate on the device before deploying the remote access VPN policy to the device.

  • Manually add client certificates to your clients. You cannot use SCEP or CA services to distribute certificates.

Secure Client guideline

Use only one Secure Client package on low-end Firewall Threat Defense devices to prevent memory exhaustion and continuous restarts.